The GSPR Checklist: Making MDR Annex I Work as Evidence
The requirement, and the document people confuse with it
Annex I to Regulation (EU) 2017/745 contains the general safety and performance requirements. It is the substantive standard the device has to meet. Article 5(2) states it without qualification: "A device shall meet the general safety and performance requirements set out in Annex I which apply to it, taking into account its intended purpose."
The GSPR checklist is not that. The checklist is a document manufacturers build to demonstrate, requirement by requirement, that Annex I has been met and to point an assessor at the evidence. The MDR never uses the word "checklist". What it demands is in Annex II, and understanding the difference is what separates a file that survives review from one that is returned.
Annex I opens by fixing the standard the whole annex serves: "Devices shall achieve the performance intended by their manufacturer and shall be designed and manufactured in such a way that, during normal conditions of use, they are suitable for their intended purpose." Everything that follows is an elaboration of that sentence.
The shape of Annex I
Annex I has three chapters, and they are not interchangeable. Assessors read them as three different kinds of question.
Chapter | Sections | What it governs | Where the evidence usually lives |
I — General requirements | 1 to 9 | Performance, risk management as a lifecycle process, the priority order for risk control, use error, lifetime, transport and storage, benefit-risk | The risk management file, usability file, stability and shipping validation |
II — Requirements regarding design and manufacture | 10 to 22 | Chemical, physical and biological properties; infection and microbial contamination; devices with a medicinal substance; materials of biological origin; construction and environment; measuring function; radiation; electronic programmable systems and software; active devices; active implantables; mechanical and thermal risks; energy or substance delivery; devices for lay users | Biocompatibility, sterilisation validation, electrical safety and EMC testing, software lifecycle records, mechanical testing |
III — Requirements regarding the information supplied with the device | 23 | Label, packaging labels, instructions for use | Label artwork, IFU, symbol justification, language plan |
Chapter I is where most first-time files are weakest, because its requirements are process requirements rather than test requirements. Section 3 requires the manufacturer to establish, implement, document and maintain a risk management system understood as a continuous iterative process across the whole lifecycle. Section 4 sets a strict order of priority for risk control: eliminate or reduce risks as far as possible through safe design and manufacture; then take protection measures including alarms; then provide information for safety. Reversing that order — warning about a hazard that could have been designed out — is a finding, not a judgement call.
What Annex II Section 4 actually asks for
The legal basis of the checklist is Section 4 of Annex II. It requires the technical documentation to contain information demonstrating conformity with the applicable general safety and performance requirements, including a justification, validation and verification of the solutions adopted. It then specifies four things the demonstration must include, and those four things are the columns of a competent GSPR checklist:
"the general safety and performance requirements that apply to the device and an explanation as to why others do not apply";
the method or methods used to demonstrate conformity with each applicable requirement;
the harmonised standards, common specifications or other solutions applied; and
the precise identity of the controlled documents offering evidence of conformity with each standard, common specification or other method applied.
Point four carries a sentence that decides how usable the checklist is: "The information referred to under this point shall incorporate a cross-reference to the location of such evidence within the full technical documentation and, if applicable, the summary technical documentation." A cross-reference is a document identifier, a version and a section — not "see biocompatibility report". A checklist whose evidence column names files that have since been revised, or that points to a folder rather than a controlled document at a stated revision, fails on this point alone, however good the underlying testing was.
This is why the checklist is described as the spine of the technical documentation. It is the only document in the file that maps every legal requirement onto a specific piece of evidence, and it is the route an assessor uses to navigate everything else. Our post on MDR technical documentation covers the structure of the file as a whole; this article stays on the requirement-to-evidence mapping inside it.
Article 8 and what presumption of conformity really buys you
Harmonised standards are the ordinary route to the third column. Article 8(1) provides: "Devices that are in conformity with the relevant harmonised standards, or the relevant parts of those standards, the references of which have been published in the Official Journal of the European Union, shall be presumed to be in conformity with the requirements of this Regulation covered by those standards or parts thereof."
Four constraints are hidden in that sentence, and each is a common finding.
Publication in the Official Journal is what matters
A standard confers presumption of conformity only where its reference has been published in the Official Journal under the MDR. An EN ISO standard that exists, is current, and is used across the industry does not carry Article 8 presumption unless it appears in the relevant Commission implementing decision. Standards harmonised under the old Directives do not carry it forward.
Presumption is partial
The presumption extends only to the requirements the standard covers, or the relevant parts of it. Applying a risk management standard does not discharge Chapter I in full, and applying an electrical safety standard does not touch biocompatibility. The checklist has to say which requirement each standard actually answers.
Deviations must be declared
A standard applied with deviations, or applied only in part, does not deliver the presumption for the parts not applied. Those parts need their own justification in the checklist.
It also covers process requirements
Article 8(1) extends the presumption to system or process requirements to be fulfilled by economic operators or sponsors, including quality management systems, risk management, post-market surveillance systems, clinical investigations, clinical evaluation and post-market clinical follow-up. That is a broader reach than manufacturers often use.
Where standards run out: common specifications
Article 9 allows the Commission to adopt common specifications where no harmonised standards exist, where they are insufficient, or where there is a public health concern. Devices conforming to them are presumed to conform to the requirements they cover. The obligation is stated firmly: "Manufacturers shall comply with the CS referred to in paragraph 1 unless they can duly justify that they have adopted solutions that ensure a level of safety and performance that is at least equivalent thereto." That escape route is closed for products listed in Annex XVI, where Article 9(4) requires compliance with the relevant common specifications outright.
"Not applicable" is a claim, and it needs a reason
The single most common defect in a GSPR checklist is a column of "N/A" entries with no accompanying justification. Annex II Section 4(a) does not permit it: the requirement is to identify the requirements that apply and to explain why the others do not. The explanation is part of the demonstration of conformity, not commentary on it.
The pattern repeats in predictable places:
Section 16, protection against radiation, marked not applicable because the device is not an X-ray unit — ignoring that the section covers unintended and stray emissions as well as intended ones.
Section 17, electronic programmable systems, marked not applicable because "the software is not a medical device" — a category error, since Section 17 applies to software incorporated in a device as well as to software that is a device.
Section 22, devices for lay users, marked not applicable on the basis of an intended purpose that the marketing material and the online listing contradict.
Section 10.4 on substances of concern, marked not applicable without any materials assessment behind the answer.
Chapter III entries marked not applicable because the device carries no printed IFU, where the Annex I exemption relied on was never assessed against the device's class and intended user.
A one-line justification that names the device characteristic responsible for the exclusion — no ionising radiation source, no measuring function, no medicinal substance, professional use only as stated in the IFU and in all promotional material — converts an assessor's question into a closed item. That sentence costs nothing to write and is the difference between a smooth review and a deficiency letter, whether the reviewer is a notified body or a competent authority looking at a Class I file.
Keeping the checklist alive
A GSPR checklist is not written once. It changes when a harmonised standard reference is superseded in the Official Journal, when a design change alters which requirements apply, when post-market surveillance data changes the risk assessment behind a Chapter I justification, and when a device is added to a family that the checklist covers. Each of those events invalidates part of the evidence column. A checklist that has not moved since the file was first compiled tells an assessor something about the whole quality system, not just about the checklist.
Where this sits in our work
Medex does not write clients' technical documentation, and we do not draft GSPR checklists on a manufacturer's behalf. The demonstration of conformity has to come from the people who designed and tested the device; nobody outside the manufacturer can honestly assert what evidence exists. What we do is act as EU Authorised Representative under Article 11, which includes verifying that the declaration of conformity and technical documentation have been drawn up and keeping a copy available for competent authorities — so we see a large number of these files and can tell you quickly whether yours reads as complete. If that is useful, our EU Authorised Representative service page explains the scope, and you can reach the team through contact.




Comments